Description
In the Linux kernel, the following vulnerability has been resolved:

block: fix dio leak on metadata mapping error

A failed integrity mapping holds a dio reference, so we need to go
through the full bio ending in case there were previously submitted
bio's in the sequence.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via resource exhaustion
Action: Patch Immediately
AI Analysis

Impact

A kernel bug causes a DIO reference to be left referenced when a metadata mapping error occurs. The retained reference prevents the underlying I/O buffer from being released, which can lead to reduced available memory, degraded performance, or a kernel panic if the leak accumulates. The impact is limited to denial of service and system instability; there is no evidence in the data that it grants code execution or privileges.

Affected Systems

All Linux distributions that use the Linux kernel without the recent patch are potentially affected. The vendor product list indicates the default Linux kernel; no specific version range is supplied, so any kernel build prior to the fix may still have the issue.

Risk and Exploitability

The EPSS score of less than 1% shows a very low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA KEV. An attacker would need to create or trigger metadata mapping errors, most likely through local privileged actions or by presenting malformed block device input. The low probability is offset by the high potential impact on availability if the leak is not addressed. The risk remains moderate, and the incident should be treated as a potential stabilization issue rather than a critical threat.

Generated by OpenCVE AI on September 19, 2026 at 05:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the DIO leak fix for block metadata mapping errors.
  • If immediate kernel upgrades are unavailable, regularly check system logs for block metadata mapping error messages and address any underlying disk or filesystem integrity issues.
  • As a temporary measure, ensure any custom block device drivers handle mapping errors gracefully and do not leave dangling DIO references.

Generated by OpenCVE AI on September 19, 2026 at 05:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: block: fix dio leak on metadata mapping error A failed integrity mapping holds a dio reference, so we need to go through the full bio ending in case there were previously submitted bio's in the sequence.
Title block: fix dio leak on metadata mapping error
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:28.339Z

Reserved: 2026-09-11T19:38:34.810Z

Link: CVE-2026-90396

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:39.310

Modified: 2026-09-17T17:17:39.310

Link: CVE-2026-90396

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T08:15:13Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime